Loyalty & Rewards Points Fraud
Points are money, and fraudsters treat them that way. From points farming to account takeover, learn how loyalty programs get drained and the controls that protect your rewards balance at checkout and login.

The moment your loyalty program lets points convert into discounts, store credit, or products, those points become a currency, and every currency attracts counterfeiters. Loyalty and rewards fraud is often overlooked because it does not show up as a chargeback. It shows up as a redemption you funded, a balance that was drained, and a program whose economics quietly stopped working.
There are two main flavors, and they need different defenses.
Flavor one: points farming
Points farming is manufacturing rewards you never intended to grant. The abuser exploits the ways your program hands out points for free or near-free.
- Signup bonuses at scale. If new members get 500 points, one person creating 60 accounts farms 30,000 points, then funnels them into redemptions.
- Action-based points loops. Points for reviews, social follows, birthday bonuses, or profile completion can each be repeated across sockpuppet accounts.
- Referral-linked points. Referring your own fake accounts to collect the referral points bonus is farming dressed as advocacy.
- Return-and-keep-points cycles. Buying to earn points, then returning the item while keeping the points, nets rewards at zero cost if your program does not claw back on refund.
Farming is fundamentally a multi-accounting problem wearing a loyalty costume. The fake members look like enthusiastic new customers; the tell is what connects them.
Flavor two: account takeover
The second flavor does not create value, it steals it. Account takeover (ATO) targets existing members who have already accumulated a real balance.
- Attackers use credential stuffing (reusing passwords leaked from other breaches) to log into loyalty accounts.
- Once inside, they drain the points into gift cards, store credit, or high-value redemptions, then cash out or resell.
- Because the account is genuine and the login "succeeds," nothing looks wrong until the real member notices their balance is gone.
ATO is especially damaging because it destroys customer trust, not just margin. The member did nothing wrong and still got robbed on your platform.
Signals to watch
Signals.
For farming:
- Signup velocity around bonus events. A surge of new members right when a bonus goes live.
- Shared device or network across many accounts. Many "members" on one device fingerprint is farming, not fandom.
- Redemption immediately after earning. Real members accumulate over time; farms earn and cash out in one sitting.
- Anonymized traffic. VPN, proxy, and Tor behind signups and redemptions, which legitimate loyal customers rarely need.
For account takeover:
- Login anomalies. A member who always logs in from one country suddenly authenticating from a datacenter IP or foreign VPN.
- Failed-login bursts. Credential-stuffing shows up as high-volume login attempts across many accounts.
- Post-login redemption spikes. Immediate max redemption after a login from a new device is a classic drain pattern.
- Contact-detail changes. Email or phone edited moments before a large redemption, to intercept confirmations.
Controls that protect the program
1. Stop cheap identity rotation.
Both farming and stuffing rely on looking like a different person each time, which means VPNs, proxies, and bots. Shieldy Fraud Filter applies checkout-level blocking for VPN, proxy, Tor, and bot traffic, cutting off the anonymized infrastructure that farms and stuffers depend on. You can also block by country and IP to shut down clustered attacks.
2. Bind points to a linked identity.
Signup bonuses, action rewards, and per-member limits should attach to the *linked person*, not the account. When device and network correlation links sockpuppets, "500 points per new member" finally means per real member. AI fraud scoring that combines device, IP, and behavioral signals is what makes that linking reliable, and Shieldy's scoring is built to weigh those signals together.
3. Claw back on refund.
Points earned on a purchase should reverse automatically when the item is returned. Without this, the buy-return-keep-points loop is free money.
4. Protect the earn-and-burn timing.
Introduce a short holding window before newly earned points become redeemable, or flag same-session earn-then-redeem behavior for review. Genuine members are unaffected; farms lose their fast cash-out.
5. Harden redemption against ATO.
Treat high-value redemptions as sensitive actions. A redemption from a new device, a foreign or datacenter network, or right after a contact-detail change should trigger verification or a hold. Blocking suspicious network traffic at the point of high-value action stops most drains cold.
A practical checklist
- Block VPN, proxy, Tor, and bot traffic to kill cheap account rotation and stuffing.
- Link accounts by device and network so per-member limits mean per person.
- Reverse points automatically on refunds.
- Add a short delay or review gate on earn-then-immediately-redeem behavior.
- Flag high-value redemptions from new devices, foreign networks, or after contact changes.
- Watch signup velocity around every bonus event.
Loyalty points are a promise you make to your best customers. Protecting the program is really about protecting that promise, so the value you set aside for genuine advocates does not get siphoned by farms and thieves.
If you want the anonymized-traffic and correlation layer running at checkout and on sensitive actions, Shieldy Fraud Filter starts free, with scaling tiers on the pricing page.
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free

